Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Problem with traceroute passing through Firewalls balanced with ACE

Hi there,

I'm having lots of problems allowing traceroute through some firewalls balanced by a couple of ace service modules (on cat 6500). As explained by the cisco configuration guide I'm using hash predictors to keep traffic persistent on the right firewall but this clearly doesn't work with traceroute because, with the exception of the last hop of a trace, the destination IP for the echo request on the way out is always different from the source IP of the echo replay on the way in. The result is that ashes calculated by the ace modules are different an traffic doesn't flow always through the same firewall.

I hope I've been clear explaining my situation and it would be great if someone could help me.

Thanks

1 REPLY
Cisco Employee

Re: Problem with traceroute passing through Firewalls balanced w

I think the only solution is that you allow your firewalls to route the icmp ttl expired message from any source.

You can't guarantee that this message will go back to the same firewall as the initial icmp echo request (or udp probes for traceroute in the unix world).

Gilles.

180
Views
0
Helpful
1
Replies
CreatePlease to create content